Git workflow, environments & CI/CD pipeline #1

Merged
cesnimda merged 6 commits from feature/git-workflow into develop 2026-07-01 11:44:35 +02:00
Showing only changes of commit 98e94a8163 - Show all commits
+13 -5
View File
@@ -17,9 +17,13 @@ jobs:
with:
fetch-depth: 0 # full history so gitleaks scans every commit
- name: Secret scan (gitleaks)
# Run the binary directly — the container-mode runner has no Docker socket,
# so `docker run` isn't available inside a job.
run: |
docker run --rm -v "$PWD:/repo" zricethezav/gitleaks:latest \
detect --source=/repo --redact --verbose --exit-code 1
GITLEAKS_VERSION=8.18.4
curl -sSL "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" -o /tmp/gitleaks.tar.gz
tar -xzf /tmp/gitleaks.tar.gz -C /tmp gitleaks
/tmp/gitleaks detect --source=. --redact --verbose --exit-code=1
dependencies:
runs-on: ubuntu-latest
@@ -31,9 +35,11 @@ jobs:
- name: Restore
run: dotnet restore InboxIntel.sln
- name: .NET vulnerable packages (fail on any)
# Match dotnet's own "has the following vulnerable packages" line rather
# than raw severity words, so package/project names can't false-positive.
run: |
dotnet list InboxIntel.sln package --vulnerable --include-transitive 2>&1 | tee vuln.txt
if grep -qiE 'Critical|High|Moderate|Low' vuln.txt; then
if grep -q "has the following vulnerable" vuln.txt; then
echo "::error::Vulnerable NuGet packages detected — see the table above."
exit 1
fi
@@ -41,6 +47,8 @@ jobs:
- uses: actions/setup-node@v4
with:
node-version: '20'
- name: npm audit (fail on high/critical)
- name: npm audit (production deps, fail on high/critical)
# Only production dependencies ship to users; dev-only toolchain advisories
# (Vite/PostCSS/etc.) shouldn't block a merge.
working-directory: frontend
run: npm audit --audit-level=high
run: npm audit --omit=dev --audit-level=high